Bug 354008 - Security flaw: Session revealed briefly before and after blanking screen
Summary: Security flaw: Session revealed briefly before and after blanking screen
Status: RESOLVED DUPLICATE of bug 388384
Alias: None
Product: kscreenlocker
Classification: Unmaintained
Component: greeter (other bugs)
Version First Reported In: unspecified
Platform: Other Linux
: NOR normal
Target Milestone: ---
Assignee: Plasma Bugs List
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2015-10-17 17:16 UTC by kdebugs
Modified: 2018-04-29 20:54 UTC (History)
5 users (show)

See Also:
Latest Commit:
Version Fixed In:
Sentry Crash Report:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description kdebugs 2015-10-17 17:16:47 UTC
The desktop / apps become visible both before turning off the screen and also if turning off the screen is canceled by user input.

Reproducible: Always

Steps to Reproduce:
0. Set screen to turn off after 1 minute, and lock the screen (Ctrl+Alt+L). Wait ~1 minute.
1. Screen briefly displays the session that's supposedly locked.
2. Then screen will blank (all black but with cursor still visible) for a few seconds before the video output is actually turned off.
3. If you press a key while the screen is blanked (before the video output is turned off), it will interrupt it and again briefly reveal the locked session before showing the lock screen.



FWIW, the revealed screen is not a cached frame, as it shows the updated clock.

Observed on SparkyLinux Live USB: KDE Plasma 5.4.1, Qt 5.4.2, Kernel 4.1.0-2-amd64
I can give you more details (hardware, boot options, etc.) if needed.

(This sort of thing has been a problem for the last 3 major versions of KDE (over a decade - for example Bug 78871 has been open since 2004).  It's the number one thing that would make me abandon KDE altogether.  I keep hoping that the entire locking system will be overhauled with security its first concern (that is its purpose after all), but I'm not getting my hopes up.  The locker remains, seemingly, merely an app added as an afterthought.  Then duct tape is applied to individual issues if they affect enough people and it's feasible.)
Comment 1 Martin Flöser 2015-12-15 17:38:15 UTC
@Kai: that sounds like related to kscreen effect?
Comment 2 Nate Graham 2018-04-29 20:54:33 UTC

*** This bug has been marked as a duplicate of bug 388384 ***